Malware

Should I remove “Lazy.215809”?

Malware Removal

The Lazy.215809 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.215809 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Arabic
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Lazy.215809?


File Info:

name: 00D49A6A3CC540E5A743.mlw
path: /opt/CAPEv2/storage/binaries/43653fe35f3e75755855682bff227045076e9da124cc79c1fdc97f41820a552a
crc32: 45E456B7
md5: 00d49a6a3cc540e5a743b190723241a6
sha1: fe37b707a27ac5034b1cd30fe794c72d4a728ebb
sha256: 43653fe35f3e75755855682bff227045076e9da124cc79c1fdc97f41820a552a
sha512: 93b0256616e1d988c6330367d1ad464b2c4304ec919eb7f3bda7058807b4ba3cdb34bc6a1a864562cf7a301d3a1b1a9a59dbf02fe8d067f0efe1fbc897964978
ssdeep: 6144:0+5b1XqLm6WvLyQ9FkWH81o0k0imsuFssuOdmIBjZKOxRGV:bXqAR9FF8+0k/CVuGmIBjgOxG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12364235EF2E579AAD4FB07BE33527BB32906B9A81B1141F497B00AEC0551CF1562930F
sha3_384: 754396e7c5db3d1b602fbe7393fc043ba1416c5dde1489e4a5fcc7c9da480cda63ef62beea6cb601acc503eef27e06d5
ep_bytes: 558bec81ec04010000b85699000083e8
timestamp: 2012-04-23 09:29:21

Version Info:

CompanyName: Mocrosuft Corporation
FileDescription: Mocrosuft Visual Studio 2010
FileVersion: 1.9.43074.5121 built by: SP1Rel
InternalName: devenv.exe
LegalCopyright: © Mocrosuft Corporation. All rights reserved.
OriginalFilename: devenv.exe
ProductName: Mocrosuft® Visual Studio® 2010
ProductVersion: 1.9.43074.5121
Translation: 0x0409 0x04b0

Lazy.215809 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.15132
MicroWorld-eScanGen:Variant.Lazy.215809
FireEyeGeneric.mg.00d49a6a3cc540e5
CAT-QuickHealFraudTool.Security
McAfeePWSZbot-FBTA!00D49A6A3CC5
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.158613
SangforInfostealer.Win32.Zbot.mt
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.a3cc54
BitDefenderThetaGen:NN.ZexaF.34606.uy1@ayGh51gG
VirITTrojan.Win32.SHeur4.BXEI
CyrenW32/A-d1ad9250!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.ABA
APEXMalicious
ClamAVWin.Trojan.Agent-1135228
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Lazy.215809
NANO-AntivirusTrojan.Win32.Zbot.dbnazh
SUPERAntiSpywareTrojan.Agent/Gen-FalComp
AvastWin32:Kryptik-OEU [Trj]
TencentMalware.Win32.Gencirc.10b696a7
Ad-AwareGen:Variant.Lazy.215809
TACHYONTrojan-Spy/W32.ZBot.332997
SophosML/PE-A + Troj/Zbot-IPP
ComodoTrojWare.Win32.Yakes.FDVN@5bypt7
BaiduWin32.Trojan.Kryptik.je
VIPREGen:Variant.Lazy.215809
TrendMicroTSPY_ZBOT.SMJC1
McAfee-GW-EditionPWSZbot-FBTA!00D49A6A3CC5
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Lazy.215809 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Lazy.215809
JiangminTrojan-Spy.Win32.Zbot.ak
GoogleDetected
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.31
ArcabitTrojan.Lazy.D34B01
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Necurs.R109444
VBA32TrojanPSW.Zbot
ALYacGen:Variant.Lazy.215809
MAXmalware (ai score=84)
MalwarebytesTrojan.Zbot.Gen
TrendMicro-HouseCallTSPY_ZBOT.SMJC1
RisingMalware.Undefined!8.C (TFE:2:d89ren5Ecj)
YandexTrojanSpy.Zbot!VFu81jas3tA
IkarusTrojan.Crypt.XPACK7
FortinetW32/Kryptik.CGEJ!tr
AVGWin32:Kryptik-OEU [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Lazy.215809?

Lazy.215809 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment